↧
90780 - Microsoft ASP.NETValidateRequest Filters Bypass Cross-Site Scripting VulnerabilityCVE-2008-3842,CVE-2008-3843
ASV Comment:
No fix is available at this time; please consider implementingmitigating controls (firewalls, traffic filtering, etc.) to address these issues. For
specific information on how to remediate these issues please consult the technical report below.
I figured if i can unregister net 2.0 from the owa site would correct this issue.
In the add/remove only dot net 4.0 is installed. When i browse C:\Windows\Microsoft.NET\Framework\ I see
06/14/2011 04:32 PM <DIR> v1.0.3705
07/13/2009 11:20 PM <DIR> v1.1.4322
06/27/2012 12:26 PM <DIR> v2.0.50727
06/14/2011 02:32 PM <DIR> v3.0
06/14/2011 04:32 PM <DIR> v3.5
08/19/2012 01:30 PM <DIR> v4.0.30319
In IIS
Default Web Site, aspnet_client, system_web 2_0_50727 & 4.0.30319 reside here with nothing in the folders when browsed.